Bookmarks¶
A curated set of reference sites I return to across engagements.
Why It Matters¶
A short, trusted set of references beats searching mid-engagement. These are the sites that reliably have the command, technique, or payload I need.
Reference¶
Technique References¶
| Resource | Use |
|---|---|
| HackTricks | Broad methodology and per-service enumeration |
| The Hacker Recipes | Active Directory and authentication attacks |
| PayloadsAllTheThings | Payloads and bypasses by category |
| GTFOBins | Unix binaries for privilege escalation and bypasses |
| LOLBAS | Windows living-off-the-land binaries |
| adsecurity.org | Deep Active Directory attack and defense |
Web Application¶
| Resource | Use |
|---|---|
| OWASP WSTG | Web testing methodology |
| PortSwigger Web Security Academy | Free labs and reference |
| HackTricks: Pentesting Web | Web service enumeration |
Vulnerabilities and Tooling¶
| Resource | Use |
|---|---|
| Exploit-DB | Public exploits and the Google Hacking Database |
| CISA KEV | Known exploited vulnerabilities |
| CVE / NVD | Vulnerability details and scoring |
| Hashcat example hashes | Identifying hash types |
Practice¶
| Resource | Use |
|---|---|
| Hack The Box | Lab machines and challenges |
| TryHackMe | Guided learning paths |
| VulnHub | Downloadable vulnerable VMs |